PMS (XBMC) Web Server Security Vulnerability - Web Server Directory Traversal Arbitrary File Access

Hi Guys,
 
Wasn't sure the appropriate forum to post this so I'm hoping this will do.
 
I've just been running some network audits on my home LAN and noticed in the nessus scan reporting a (most likely) default configuration issue that need attention.
 
--
Web Server Directory Traversal Arbitrary File Access

Synopsis
The remote web server is affected by a directory traversal vulnerability.

Description
It appears possible to read arbitrary files on the remote host outside the web server’s document directory using a specially crafted URL. An unauthenticated attacker may be able to exploit this issue to access sensitive information to aide in subsequent attacks.

Note that this plugin is not limited to testing for known vulnerabilities in a specific set of web servers. Instead, it attempts a variety of generic directory traversal attacks and considers a product to be vulnerable simply if it finds evidence of the contents of ‘/etc/passwd’ or a Windows ‘win.ini’ file in the response. It may, in fact, uncover ‘new’ issues, that have yet to be reported to the product’s vendor.

Solution
Contact the vendor for an update, use a different product, or disable the service altogether.

Plugin Information

Plugin ID:
10297

Plugin Version:
$Revision: 1.104 $

Plugin Type:
remote

Plugin Publication Date:
1999/11/05

Plugin Last Modification Date:
2013/04/04
Risk Information

Risk Factor:
Medium

CVSS Base Score: 
5.0

CVSS Vector Score:
CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Temporal Vector: 
CVSS2#E:F/RL:OF/RC:C

CVSS Temporal Score:
4.1
Vulnerability Information
 
Exploit Available: 
true

Exploitability Ease:
Exploits are available

Exploitable With: Metasploit (Indusoft WebStudio NTWebServer Remote File Access) 

 

Reference Information
 
cve: CVE-2013-2619 CVE-2012-5641 CVE-2012-5344 CVE-2012-5335 CVE-2012-5100 CVE-2012-1464 CVE-2012-0697 CVE-2011-4788 CVE-2011-2524 CVE-2011-1900 CVE-2010-4181 CVE-2010-3743 CVE-2010-3488 CVE-2010-3487 CVE-2010-3459 CVE-2010-1571 CVE-2008-5315 CVE-2000-0920

osvdb: 89293 88925 82678 82647 80586 79653 78308 78307 74135 73413 72972 72498 72231 70176 68962 68880 68538 68141 68089 68026 65285 64611 64532 50288 3681

bid: 58794 57313 57143 56871 52541 52327 51399 51311 48926 48114 47987 47842 47760 45603 45599 44586 44564 44393 43830 43358 43356 43258 43230 40680 40133 40053 32412 7715 7544 7378 7362 7308

edb-id: 24915
 

Plugin Output

3000 / tcp
Service: www
 
Nessus was able to retrieve the remote host’s password file using the following URL :

http://lounge-room-mac-mini.local.:3000/../../../../../../../../../../../../etc/passwd
Here are the contents :

------------------------------ snip ------------------------------
##
# User Database
#
# Note that this file is consulted directly only when the system is running
# in single-user mode. At other times this information is provided by
# Open Directory.
#
# See the opendirectoryd(8) man page for additional information about
# Open Directory.
##
nobody:*:-2:-2:Unprivileged User:/var/empty:/usr/bin/false
root:*:0:0:System Administrator:/var/root:/bin/sh
etc...
 

 

Well.... look at that... crazy.

I'd post in the PMS forum as well, just to be safe. 

Also, PMS is totally proprietary and has nothing to with XBMC, but better safe than sorry. 

I thought PMS was derivative of XBMC.

If not, then why does the PMS port 3000 web server call itself XBMC?

Looks like somebody reported this in XBMC nearly 12 months ago:

http://forum.xbmc.org/showthread.php?tid=144110

and a couple of years before that:

http://forum.xbmc.org/showthread.php?tid=81173

and likely prior to that as well.

Plex Media Center (PMC) and Plex Home Theater (PHT) both are, but Plex Media Server (PMS) is not based on XBMC.  

At least as far as I know. 

Edit: Yea, that's strange.  I'm not sure why PMS would be doing anything with port 3000...  unless you are actually referring to PMC/PHT and said PMS by mistake? 

But that's odd too... because what web server functions would PHT/PMC be running, when all "server" functions are served by PMS? Maybe the iOS/Android remote server or something...? 

It's definitely PMS running on a Mac Mini that happens to be running the Plex Client as well.

At least it calls itself "PLEX Media Server" Version 0.9.8.4.125-ffe2a5d

I hadn't considered it could be the PMC causing this... but apparently it is!

So how do we get this bug fixed?

bash-3.2# lsof -i :3000
COMMAND   PID        USER   FD   TYPE             DEVICE SIZE/OFF NODE NAME
Plex    94884 mediaserver   20u  IPv4 0xadbe01c83f8c714f      0t0  TCP *:hbci (LISTEN)
bash-3.2# lsof -n +c 0 -V -i| grep -i plex
PlexHelper              375     mediaserver    1u  IPv4 0xadbe01c83b55ea97      0t0  UDP *:59299
PlexHelper              375     mediaserver    2u  IPv4 0xadbe01c84a8e733f      0t0  UDP *:62562
Plex\x20Media\x20Serv 61777     mediaserver   24u  IPv6 0xadbe01c842327c2f      0t0  TCP *:32443 (LISTEN)
Plex\x20Media\x20Serv 61777     mediaserver   39u  IPv6 0xadbe01c83daa73ef      0t0  TCP *:32400 (LISTEN)
Plex\x20Media\x20Serv 61777     mediaserver   56u  IPv6 0xadbe01c83f3c33ef      0t0  TCP 127.0.0.1:32400->127.0.0.1:58904 (TIME_WAIT)
Plex\x20Media\x20Serv 61777     mediaserver   60u  IPv4 0xadbe01c83a35edcf      0t0  UDP *:52102
Plex\x20Media\x20Serv 61777     mediaserver   67u  IPv4 0xadbe01c83a35d23f      0t0  UDP *:32410
Plex\x20Media\x20Serv 61777     mediaserver   68u  IPv4 0xadbe01c83a35c477      0t0  UDP *:32413
Plex\x20Media\x20Serv 61777     mediaserver   69u  IPv4 0xadbe01c83a35bfdf      0t0  UDP 127.0.0.1:55428
Plex\x20Media\x20Serv 61777     mediaserver   70u  IPv4 0xadbe01c83a35b6af      0t0  UDP 192.168.1.84:50527
Plex\x20Media\x20Serv 61777     mediaserver   71u  IPv4 0xadbe01c83ee40b97      0t0  UDP 127.0.0.1:53925
Plex\x20Media\x20Serv 61777     mediaserver   72u  IPv4 0xadbe01c83b55de57      0t0  UDP 192.168.1.84:57526
Plex\x20DLNA\x20Serve 61780     mediaserver   11u  IPv4 0xadbe01c843dd9fbf      0t0  TCP 127.0.0.1:53278->127.0.0.1:53277 (CLOSE_WAIT)
Plex\x20DLNA\x20Serve 61780     mediaserver   16u  IPv4 0xadbe01c83a35c2ef      0t0  UDP *:ssdp
Plex\x20DLNA\x20Serve 61780     mediaserver   19u  IPv4 0xadbe01c83fb03c9f      0t0  TCP *:blueberry-lm (LISTEN)
Plex\x20DLNA\x20Serve 61780     mediaserver   22u  IPv4 0xadbe01c8498d74c7      0t0  UDP *:9094
Plex\x20DLNA\x20Serve 61780     mediaserver   25u  IPv4 0xadbe01c83b55f6d7      0t0  UDP *:7572
Plex\x20DLNA\x20Serve 61780     mediaserver   28u  IPv4 0xadbe01c83b55f23f      0t0  UDP *:bnt-manager
Plex\x20DLNA\x20Serve 61780     mediaserver   31u  IPv4 0xadbe01c843dd7ba7      0t0  TCP *:32469 (LISTEN)
Plex\x20DLNA\x20Serve 61780     mediaserver   34u  IPv4 0xadbe01c83ee411b7      0t0  UDP *:62760
Plex\x20DLNA\x20Serve 61780     mediaserver   37u  IPv4 0xadbe01c83a35c5ff      0t0  UDP *:62026
Plex\x20DLNA\x20Serve 61780     mediaserver   55u  IPv4 0xadbe01c83b5624c7      0t0  UDP 192.168.1.84:61844->192.168.1.254:nat-pmp
Plex\x20DLNA\x20Serve 61780     mediaserver   60u  IPv4 0xadbe01c83a35edcf      0t0  UDP *:52102
Plex\x20DLNA\x20Serve 61780     mediaserver   61u  IPv6 0xadbe01c83c348c2f      0t0  TCP [::127.0.0.1]:32400->[::127.0.0.1]:53272 (TIME_WAIT)
Plex\x20DLNA\x20Serve 61780     mediaserver   62u  IPv6 0xadbe01c8410ee3ef      0t0  TCP [::127.0.0.1]:32400->[::127.0.0.1]:53273 (TIME_WAIT)
Plex\x20DLNA\x20Serve 61780     mediaserver   63u  IPv6 0xadbe01c83ca993ef      0t0  TCP [::127.0.0.1]:32400->[::127.0.0.1]:53274 (TIME_WAIT)
Plex                  94884     mediaserver    3u  IPv4 0xadbe01c8449db18f      0t0  UDP *:*
Plex                  94884     mediaserver   13u  IPv4 0xadbe01c8449da85f      0t0  UDP *:32415
Plex                  94884     mediaserver   14u  IPv4 0xadbe01c83b55eda7      0t0  UDP 127.0.0.1:50097
Plex                  94884     mediaserver   15u  IPv4 0xadbe01c8449da9e7      0t0  UDP 192.168.1.84:59729
Plex                  94884     mediaserver   16u  IPv4 0xadbe01c83a35d6d7      0t0  UDP *:32412
Plex                  94884     mediaserver   20u  IPv4 0xadbe01c83f8c714f      0t0  TCP *:hbci (LISTEN)
Plex                  94884     mediaserver   21u  IPv4 0xadbe01c83ee5ac9f      0t0  TCP *:websm (LISTEN)
Plex                  94884     mediaserver   22u  IPv4 0xadbe01c8498d71b7      0t0  UDP *:9777

Well, PMC will not be receiving any future updates. PHT, when released, will take its place. That said, PHT is still based on XBMC code (12.2), so I wonder if the bug is still there in PHT?


The rest of the technical details are over my head, but I do see the process listening on 32400, which would make it PMS and not PMC, I think.


And truthfully, I’m not sure the best way to bring this to anyone’s attention.

Well, as I said, this is actually in PMC so it's possible nobody will actually care (sadly).  (hbci is port 3000 as listed in OS X's /etc/services)

I'm going to take a stab in the dark and guess that PHT will have the same problem, but I've not tried it yet.  Now might be the time to have a closer look at it (I thought it was mean to be a replacement for both PMC and PMS though...)

PHT is in the clear - so just an issue with PMC.